An Empirical Comparison of Security and Privacy Characteristics of Android Messaging Apps

Conference Paper (2026)
Author(s)

Ioannis Karyotakis (National Technical University of Athens, Athens University of Economics and Business)

Foivos Timotheos Proestakis (Athens University of Economics and Business, National Technical University of Athens)

Evangelos Talos (Athens University of Economics and Business, National Technical University of Athens)

Diomidis Spinellis (Athens University of Economics and Business, TU Delft - Electrical Engineering, Mathematics and Computer Science)

Nikolaos Alexopoulos (Athens University of Economics and Business)

Research Group
Software Engineering
DOI related publication
https://doi.org/10.1145/3748522.3779858 Final published version
More Info
expand_more
Publication Year
2026
Language
English
Research Group
Software Engineering
Pages (from-to)
1248-1249
Publisher
ACM
ISBN (electronic)
9798400722943
Event
41st Annual ACM Symposium on Applied Computing, SAC 2026 (2026-03-23 - 2026-03-27), Thessaloniki, Greece
Page Views
49
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Mobile messaging apps are central to user privacy, yet their practical implementations remain understudied. Using a hybrid static-dynamic methodology, we compare the Android clients of Meta Messenger, Signal, and Telegram. Our results show clear differences: Signal has the smallest attack surface, Messenger exhibits extensive background activity, and Telegram requests the most high-risk permissions. All three apps comply with the Android permission model.